CVE-2018-20570: Medium severity jasper reports vulnerability
jp2encode in jp2/jp2enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-20570?
CVE-2018-20570 is a vulnerability in JasPer 2.0.14 that allows for a heap-based buffer over-read in the jp2_encode function.
How severe is CVE-2018-20570?
CVE-2018-20570 has a severity rating of 6.5 (medium).
What is the affected software for CVE-2018-20570?
The affected software for CVE-2018-20570 includes Jasper Project Jasper version 2.0.14 and Debian Debian Linux 8.0.
How can I fix CVE-2018-20570?
To fix CVE-2018-20570, it is recommended to update to a patched version of JasPer or apply the necessary security patches provided by the vendor.
Where can I find more information about CVE-2018-20570?
More information about CVE-2018-20570 can be found in the references: http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00082.html, http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00085.html, and https://github.com/mdadams/jasper/issues/191.